9ce6ae37be
- Em dashes: 1712 remplaces par tirets simples (86 fichiers + _index.md, en-tete section Limagrain conserve) - Checklists: 24 '- [ ]' -> '- ☐' (3 pages operations, plus de todos Obsidian) - Ancres: 33 reparees (slugs GitHub + ancres HTML <a id> reconnues), 1 reciblee (manuel de reten) - related: tenseflow -> tense-flow, pie -> mechanical-elements, group.md retire (doublon shipping) - Registre: compteur global 122 -> 131 pages - Rapport racine _lint_report.md mis a jour (scan v2 + re-scan final: 0 anomalie) - Aucun fichier limagrain/ modifie (cloisonnement)
171 lines
8.8 KiB
Markdown
171 lines
8.8 KiB
Markdown
---
|
|
title: "Security"
|
|
type: architecture
|
|
sources:
|
|
- areas/security/index.md (404 - compiled from cross-source knowledge)
|
|
- areas/parameters.md
|
|
- areas/inventory_management/stations/roles.md
|
|
- modules cross-source knowledge
|
|
- custom/analyse_fonctionnelle.md
|
|
related:
|
|
- architecture/overview.md
|
|
- architecture/application-dictionary.md
|
|
- modules/billing-3pl.md
|
|
- modules/3pl-portal.md
|
|
- modules/owner-extensions.md
|
|
last_compiled: "2026-04-26"
|
|
---
|
|
|
|
# Security
|
|
|
|
## Overview
|
|
|
|
Easy WMS security is built around a role-based access control (RBAC) model layered over a multi-tenant site architecture. Each user belongs to one or more **roles** that grant access to specific UI areas, commands, and data scopes. Security operates at three levels: authentication (who you are), authorization (what you can do), and data isolation (what data you can see).
|
|
|
|
## User Roles
|
|
|
|
Easy WMS defines a role hierarchy with increasing privileges:
|
|
|
|
| Role | Scope | Capabilities |
|
|
|------|-------|-------------|
|
|
| **SuperAdmin** | Organization (all sites) | Full access including user management, system parameters, all modules |
|
|
| **Administrator** | Organization or per-site | Most functional areas; may be scoped to one warehouse |
|
|
| **Manager** | Per-site | Operational supervision; can release orders, manage counts, view reports |
|
|
| **Operator** | Per-site | Execute daily operations: picking, receiving, counting, shipping |
|
|
| **RF Operator** | RF terminal only | Subset of Operator; limited to terminal flows |
|
|
| **Viewer / Read-only** | Per-site | Read-only access to views and reports |
|
|
| **3PL Client** | Owner-scoped | Only sees data for their owner; requires 3PL Portal module |
|
|
| **SCEM Admin** | Cross-site | Manages Supply Chain Event subscriptions and notification routing |
|
|
|
|
Custom roles can be defined in the AD to grant fine-grained access to specific Commands, Views, and Dialogs.
|
|
|
|
## Authentication
|
|
|
|
### Standard login
|
|
- **Web (SmartUI)**: Username/password authentication; session managed via encrypted cookie
|
|
- **RF Terminals**: Username/password entered at terminal login screen; sessions can be configured to time out after inactivity
|
|
- **API (ERP Integration)**: API key or service account credentials; configured per integration endpoint
|
|
|
|
Password policies (minimum length, complexity, expiry) are configurable in system parameters.
|
|
|
|
### QR Code login (RF terminals)
|
|
|
|
Operators can log in to RF terminals by scanning a personal QR Code instead of typing their credentials:
|
|
|
|
- The QR Code contains **anonymized data** - a third party who finds a lost QR Code cannot derive the operator's username or password from it
|
|
- **Each reprint invalidates the previous QR Code** - there is no revocation mechanism other than reprinting
|
|
- QR Code login is **incompatible with SSO**: a user configured for SSO cannot use QR Code login
|
|
|
|
### SSO (Single Sign-On)
|
|
|
|
EasyWMS supports SSO using the **SAML V2.0 protocol**. No other SSO protocol is supported.
|
|
|
|
- SSO is available on both the **PC (SmartUI)** and **RF terminal** interfaces
|
|
- When SSO is enabled for a user account, EasyWMS will **not accept any other login method** for that user - standard username/password login is disabled
|
|
- **SSO and QR Code are mutually exclusive**: enabling SSO on a user account prevents them from using QR Code login
|
|
- Configuration requires setting up the SAML identity provider (IDP) in EasyWMS system parameters and mapping EasyWMS roles to IDP groups
|
|
|
|
## Authorization Model
|
|
|
|
Authorization is evaluated at two levels:
|
|
|
|
### Menu / UI Access
|
|
Each Role grants access to specific navigation areas. A user who cannot access a menu item cannot reach the underlying Commands or Views from the UI.
|
|
|
|
### Command-Level Access
|
|
Individual AD Commands can be restricted to specific roles. This is enforced server-side - even if a user constructs an API call directly, the command execution checks the caller's role.
|
|
|
|
### Data Scope (Owner Isolation)
|
|
When the **Owner Extensions** module is active, data is isolated by owner:
|
|
- Receipt orders, shipping orders, and master data (items, suppliers, accounts) carry an owner code
|
|
- Users assigned to a specific owner can only see and act on that owner's data
|
|
- 3PL Portal users have this isolation enforced automatically
|
|
- See [Owner Extensions](../modules/owner-extensions.md) for details
|
|
|
|
## Station Roles
|
|
|
|
Beyond system roles, operators are assigned to **station roles** that determine which warehouse stations they can work at. Station roles are configured per station type:
|
|
- An operator with "Receiving" role can work at Dock and PIE stations
|
|
- An operator with "Picking" role can work at PK/PS/ME stations
|
|
- An operator can hold multiple station roles simultaneously
|
|
|
|
Station role assignment is done in the Warehouse Designer or via the Stations administration view.
|
|
|
|
## Audit Trail
|
|
|
|
Every significant operation in Easy WMS generates a **Transaction** record:
|
|
- Who performed the operation (user)
|
|
- When (timestamp)
|
|
- What (transaction type code, e.g., STK.ADJ, CON.MOVE)
|
|
- On which objects (container, location, item, order)
|
|
- From which equipment (RFT, workstation IP)
|
|
|
|
Transactions are immutable and cannot be deleted. They form the complete audit trail for stock movements, adjustments, order processing, and user actions. See [Transactions](../concepts/transactions.md) for the full transaction type catalog.
|
|
|
|
## Quality Locks (Stock Security)
|
|
|
|
Quality Control uses a two-tier lock system to prevent unauthorized stock movements:
|
|
- **Receiving status**: Set automatically during reception; cleared when stock passes QC
|
|
- **User status**: Set manually or via ERP STR message; cleared manually or via time-based unlock
|
|
|
|
Stock with an active lock cannot be assigned to shipping orders or moved by standard tasks. This provides a safety mechanism to prevent inadvertent shipment of quarantined stock. See [Quality Control](../concepts/quality-control.md) for details.
|
|
|
|
## Container Locks
|
|
|
|
Containers can be locked with specific lock types that prevent certain operations:
|
|
|
|
| Lock Type | Blocked Operation |
|
|
|-----------|------------------|
|
|
| Inbound lock | Container cannot receive new stock |
|
|
| Outbound lock | Container cannot be picked or shipped |
|
|
| Movement lock | Container cannot be moved to another location |
|
|
| Blocking lock | All operations blocked |
|
|
|
|
Container lock events generate `LCK.CON.001` and `ULK.CON.001` transactions.
|
|
|
|
## Network and Infrastructure Security
|
|
|
|
- **IIS Application Pools**: Run under dedicated service accounts with minimal OS privileges
|
|
- **Database**: Separate credentials per application pool; principle of least privilege
|
|
- **API Keys**: ERP integration uses API keys per connection; keys are rotated per customer policy
|
|
- **HTTPS**: All SmartUI and API traffic encrypted via TLS; HTTP redirects to HTTPS enforced
|
|
- **RF WIFI**: RF terminals communicate over WPA2/WPA3 encrypted WIFI networks
|
|
- **AGV Communication**: AGV systems communicate over dedicated network segments (VLAN isolation recommended)
|
|
- **VPN**: SaaS deployments require VPN tunnels for on-premise ERP integration and printer connectivity
|
|
|
|
## Notification Security
|
|
|
|
The SCEM (Supply Chain Event Management) module allows subscribing to operational events. Subscriptions are scoped by role:
|
|
- **SuperAdmin/Administrators/Managers**: Can subscribe to any event type
|
|
- **3PL clients**: Can only subscribe to events related to their owner
|
|
- Notification channels (email, SMS, web) are configured per subscription
|
|
|
|
## Parameters Affecting Security
|
|
|
|
| Parameter | Effect |
|
|
|-----------|--------|
|
|
| `SESSION_TIMEOUT_MINUTES` | RF and web session inactivity timeout |
|
|
| `PASSWORD_MIN_LENGTH` | Minimum password length |
|
|
| `MAX_LOGIN_ATTEMPTS` | Account lockout threshold |
|
|
| `AUDIT_LOG_RETENTION_DAYS` | How long transaction logs are kept |
|
|
|
|
## Common Errors
|
|
|
|
| Symptom | Cause | Solution |
|
|
|---------|-------|---------|
|
|
| User cannot access a menu | Role missing required permission | Add the menu item to the user's role in AD configuration |
|
|
| RF terminal login rejected | User has no station role at that station type | Assign appropriate station role |
|
|
| ERP API calls return 401 | API key expired or invalid | Regenerate API key in integration configuration |
|
|
| Stock cannot be assigned (locked) | User or receiving status active | Check Quality Control view; unlock if appropriate |
|
|
| 3PL client sees other owners' data | Owner Extensions not configured | Enable Owner Extensions module and assign owner to user |
|
|
|
|
## Related
|
|
|
|
- [Overview](overview.md) - System architecture and deployment model
|
|
- [Application Dictionary](application-dictionary.md) - Role and permission configuration via AD
|
|
- [Transactions](../concepts/transactions.md) - Audit trail for all operations
|
|
- [Quality Control](../concepts/quality-control.md) - Stock lock system
|
|
- [Owner Extensions](../modules/owner-extensions.md) - Multi-owner data isolation
|
|
- [3PL Portal](../modules/3pl-portal.md) - External client access model
|
|
- [Supply Chain Event Management](../modules/supply-chain-event.md) - Notification subscriptions
|